HIGH
GHSA-hqjg-pww4-pcgq
@google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script
Quick fix
GHSA-hqjg-pww4-pcgq — @google/clasp: upgrade to the fixed version with the command below.
npm install @google/clasp@3.2.0Details
### Impact Allows an attacker to perform a "Path Traversal" attack to modify files outside the projects directory, potentially allowing for running attacker code on the developer's machine.
### Patches Fixed in version 3.2.0
### Workarounds * Only clone or pull scripts from trusted sources * Review the output of the `pull` and `clone` commands to verify only expected project files are modified
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/google/clasp/security/advisories/GHSA-hqjg-pww4-pcgq[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-4092[ADVISORY]
- https://github.com/google/clasp/pull/1109[WEB]
- https://github.com/google/clasp/commit/ba6bd666fe74de54950122b5d92ecf1dcc02a9d3[WEB]
- https://github.com/google/clasp[PACKAGE]
- https://github.com/google/clasp/releases/tag/v3.2.0[WEB]